PT-2026-39217 · Grimmory · Grimmory
Acfirthh
·
Published
2026-05-08
·
Updated
2026-05-09
·
CVE-2026-42451
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Grimmory versions prior to 2.3.1
Description
A stored cross-site scripting (XSS) issue in the browser-based EPUB reader allows an attacker to embed arbitrary JavaScript within a crafted EPUB file. When a user opens the affected book, the script executes in the browser with full access to the application's session context. This can lead to session token theft and account takeover, including administrative access if an administrator opens the file.
Recommendations
Update to version 2.3.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grimmory